InternROIINTERNSHIP MANAGEMENT PLATFORM

Privacy notice

Last updated 28 August 2026

Draft — not yet reviewed by a lawyer

This text describes accurately what the software does with data, and is intended as the starting point for review by a qualified adviser in the relevant jurisdiction. It is not legal advice and is not in force. Passages in square brackets are decisions that have not been made yet.

1. Who this is about

The Internship ROI Simulator ("the Service") is operated by Opportunities Nearby FZE, Sharjah Research Technology and Innovation Park (SRTIP), Sharjah, United Arab Emirates — Licence No. 11131 ("we").

Two different relationships matter here, and they carry different duties:

This split follows the controller and processor definitions in the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021 — the "PDPL"), which applies to us as an SRTIP establishment, and it holds: we are controller for account holders, and processor for the people an employer adds. Because the PDPL requires a processor to act on the controller's documented instructions, we put a written data-processing agreement in place with each customer — if your organisation does not have one yet, ask at the address in section 10 and we will provide it. Where another regime also applies to a customer — the GDPR, or the DIFC or ADGM data-protection laws — that agreement is where its requirements are addressed.

2. What the Service stores

Everything the Service holds falls into five groups.

Analytics. With your consent, the Service uses Google Analytics (GA4) to understand how its pages are used. Nothing loads until you actively accept a banner shown on first visit; declining, or leaving it unanswered, leaves the Service exactly as before — no third-party script runs, and no cookie is set beyond the one that keeps you signed in. The Service sets no advertising or profiling cookie of any kind, and analytics data is never sold.

3. Where it is stored, and who else touches it

The database and uploaded files are hosted on Supabase in the eu-central-2 region (Zurich, Switzerland). The application itself is served by Cloudflare from its global edge network. This means personal data about people in the United Arab Emirates is stored outside the UAE.

Switzerland was chosen for this reason. It holds an adequacy decision from the European Commission and appears on the lists of adequate jurisdictions published by the ADGM and the DIFC, and its own Federal Act on Data Protection applies to the data while it is there.

The UAE Data Office has not yet published the PDPL's executive regulations or an adequacy list of its own. Until it does, we rely on Article 23 of the PDPL, which permits a transfer out of the UAE under a contract holding the recipient to the PDPL's standard of protection: Supabase's data-processing addendum, which incorporates the EU standard contractual clauses, is that contract, and Swiss data-protection law applies to the data while it is in Zurich. If the Data Office publishes rules that ask for more, we will comply and update this notice.

Our processors are:

Consent is the basis for this transfer, and it suffices: Article 23 of the PDPL permits a transfer made with the data subject's express consent, and nothing is sent to Google unless a visitor actively accepts the banner. For visitors protected by the GDPR, Google LLC is additionally certified under the EU–U.S. Data Privacy Framework, which the European Commission has found adequate. Declining the banner keeps this paragraph from applying to you at all.

We do not sell personal data, and we do not share it for anyone else's marketing.

4. Who can see what

Access is enforced in the database itself, not only in the interface, so a person cannot reach data by guessing a web address:

Uploaded files are held in private storage with no public address. When a file is opened, the Service issues a link that expires after five minutes.

5. Report share links

An administrator can create a link that shows a generated report to someone without an account. Anyone holding that link can read the report until it expires or is withdrawn, so it should be treated as confidential.

A shared report contains programme-level figures — cost, return, delivery counts and KPI results. It does not name individual interns and does not include their submissions, feedback or individual ratings. The Service records when a link is opened and how many times, and keeps that record after the link is withdrawn.

6. How long it is kept — and what cannot be deleted

Some records in the Service are deliberately permanent. Submissions, reviews, ratings, KPI measurements, saved ROI snapshots and the audit log are append-only: the software refuses to delete or rewrite them, so that a performance record cannot be quietly altered after the fact and a report can always be reproduced from what was true when it was generated.

That protection has a cost, and we would rather state it than hide it: a request to erase an individual's assessment history cannot be satisfied by deleting those rows. Where erasure is required by law, it would have to be met by removing the identifying fields that link a record to a person, or by deleting the organisation's account in full.

Retention periods are:

Erasure requests go to the address in section 10 and are executed by us within 30 days: for the append-only records above, by removing the fields that link a record to a person; for everything else, by deletion. Where the employer is the controller, we act on the employer's instruction.

7. Your rights

Subject to the law that applies to you, you may ask for a copy of your data, ask for inaccurate data to be corrected, object to or restrict how it is used, or ask for it to be deleted — bearing section 6 in mind. If an employer entered your data, please ask them first; we will help them respond.

You can correct your own name and profile picture at any time on the My account screen.

8. Young people

Interns are often students and may be under 18. The Service has no age gate and never asks a person's date of birth, because an employer — not the software — decides who joins a programme. Where an intern is a minor, the employer is responsible for having a lawful basis to record their performance, including any consent a guardian must give.

For UAE programmes the position is this: the Labour Law (Federal Decree-Law No. 33 of 2021) already requires an employer taking on anyone aged 15 to 17 to hold a juvenile work permit and the written consent of the person's guardian, and that consent must cover the recording of the intern's work and performance that the programme involves. We hold no more data about a minor than about any other intern, and every protection in this notice applies equally. An employer running a programme under another jurisdiction's rules on children's data is responsible for meeting them before adding the intern.

9. Security

Access rules are enforced by the database on every read and write. Files are private by default and reachable only through short-lived links. Passwords are stored as hashes. Administrative actions are written to an append-only audit log.

No system is perfectly secure. If a breach affects your data we will act on the notification duties that apply to us. If a breach is likely to prejudice your privacy or the security of your data, we will notify the UAE Data Office and — where the risk to you is serious — you directly, without undue delay and in any event within 72 hours of becoming aware of it. The PDPL sets no numeric deadline until its executive regulations are published; 72 hours is the strictest standard among the regimes that touch this Service, so it is the one we adopt. Where we hold data as an employer's processor, we notify the employer without undue delay so it can meet its own duties.

10. Contact and changes

Questions about this notice or a request about your data: support@internroi.com, Block B, B55-200, Sharjah Research Technology and Innovation Park (SRTIP), Sharjah, United Arab Emirates. A Data Protection Officer is not currently required and none is appointed: the PDPL requires one only for high-risk processing — large-scale or systematic evaluation of sensitive personal data, or novel technologies — and performance records are not sensitive data as the PDPL defines it, nor is our scale large. Privacy questions sent to the address above reach the people who operate the Service directly. We will revisit this when the executive regulations are published or if what we process changes.

If we change this notice we will update the date at the top and, where the change is significant, tell account holders directly.

InternROI · Privacy · Terms